Info
2026-08-17 22:04Z · last 4h · 12 findings
· glm-5.2:cloud
Threat Brief — 2026-08-17 — Pipeline injection and logistics fallout
Executive summary
Two new critical vulnerabilities demand immediate patching: an unauthenticated GitLab GraphQL flaw allowing remote modification or deletion of public projects, and a Snowflake GitHub Actions workflow injection enabling command execution via crafted issues. Separately, the CEVA Logistics breach has now been confirmed to affect Pokémon Center customers in the UK and Germany, expanding the third-party supply-chain incident beyond Valve's Steam hardware customers. Adam Shostack also published a new lightweight LLM threat model ("PHANTOM-B") in response to the Hugging Face agent breach — the first structured modeling framework to emerge from that incident.
Top items
- Critical GitLab GraphQL vulnerability (unauthenticated project modification/deletion) — GitLab has shipped security updates for CE and EE addressing a flaw that lets unauthenticated attackers remotely modify or delete public projects under certain conditions. Any organisation running self-hosted GitLab should patch immediately, as public project integrity is at risk without credentials. (src: The Hacker News)
- Snowflake GitHub Actions command-injection vulnerability — Wiz disclosed a workflow injection flaw in Snowflake's public
snowflakedb/snowflake-connector-netrepository where crafted GitHub issues can trigger arbitrary command execution. This is a CI/CD supply-chain risk: any fork-based or issue-driven Actions workflow using untrusted input without proper sanitisation is vulnerable to the same pattern. (src: The Hacker News)
- CEVA Logistics breach expands to Pokémon Center (developing) — The third-party logistics breach first reported as affecting Valve Steam hardware customers (2026-08-10, BleepingComputer) now extends to Pokémon Center customers in the UK and Germany, with personal and order data stolen. CEVA Logistics is the common vector — organisations using CEVA should audit what customer data was shared and assess notification obligations. (src: BleepingComputer)
- Adam Shostack releases PHANTOM-B LLM threat model (developing) — Following the Hugging Face autonomous-agent breach first reported 2026-07-20 (The Hacker News), threat-modeling expert Adam Shostack published a new "lightweight yet usable" threat model for LLMs called PHANTOM-B. This is the first structured threat-modeling framework to emerge from the incident and is relevant for teams building or deploying agentic AI systems. (src: Dark Reading)
- Cavern C2 evolution detailed by Kaspersky (developing) — The Cavern/Cav3rn C2 framework, first reported 2026-08-12 (SecurityLab) as used by Iranian nation-state actors against Israeli entities, has been further analysed by Kaspersky. The framework continues to blend C2 traffic into DNS and Google Apps Script channels, making detection difficult without dedicated DNS monitoring and Google Apps Script execution logging. (src: The Hacker News)
Themes
- CI/CD and developer-platform attack surface — Both the GitLab GraphQL flaw and the Snowflake GitHub Actions injection target developer infrastructure where untrusted input flows into privileged operations. The pattern is consistent: public-facing functionality (project APIs, issue trackers) lacking input validation before executing in high-privilege contexts. Teams should audit all Actions workflows and API endpoints that accept unauthenticated input.
- Third-party logistics as breach multiplier — CEVA Logistics now links breaches at both Valve and Pokémon Center, illustrating how a single supplier compromise cascades across multiple brands. Customer order data shared with fulfilment partners is a recurring blind spot in vendor risk management.
